nerdexam
(ISC)2

CSSLP · Question #353

Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?

The correct answer is D. DoD 5200.40. DoD Directive 5200.40 established the Defense Information Technology Security Certification and Accreditation Process (DITSCAP) as the mandatory C&A framework for all DoD information systems. DITSCAP has since been superseded by the DIACAP and later the RMF.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?

Options

  • ADoD 8910.1
  • BDoD 5200.22-M
  • CDoD 8000.1
  • DDoD 5200.40

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    2% (1)
  • D
    88% (37)

Why each option

DoD Directive 5200.40 established the Defense Information Technology Security Certification and Accreditation Process (DITSCAP) as the mandatory C&A framework for all DoD information systems. DITSCAP has since been superseded by the DIACAP and later the RMF.

ADoD 8910.1

DoD 8910.1 is not a recognized directive defining DITSCAP.

BDoD 5200.22-M

DoD 5200.22-M refers to the National Industrial Security Program Operating Manual (NISPOM), which covers safeguarding classified information in industry, not the DITSCAP process.

CDoD 8000.1

DoD 8000.1 is related to the Management of DoD Information Resources and Information Technology, a broader directive that does not specifically define DITSCAP.

DDoD 5200.40Correct

DoD Directive 5200.40, titled "Defense Information Technology Security Certification and Accreditation Process (DITSCAP)," officially defined and mandated DITSCAP as the standard framework for certifying and accrediting information systems within the Department of Defense.

Concept tested: DoD DITSCAP Directive

Topics

#DITSCAP#C&A#DoD Policy#Security Directives

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice